Kevin Ostrin

Director of Application/Product Security | Specializing in Application and Infrastructure Security | Building and Leading High Performing Security Teams | Secure Code Development | OSCE, OSCP, CISSP

Role
Director of Application and Product Security at Aon
Location
Lehi, UT, US
LinkedIn followers
500 followers

About Kevin Ostrin

Seasoned security leader with over 11 years of dedicated experience in cybersecurity, with a proven ability to spearhead organization-wide security initiatives, integrating security principles into product lifecycles and infrastructure roadmaps. Demonstrated ability to grow and foster high-performing Penetration Testing/Offensive Security teams. Adept at collaborating with diverse cross-functional teams to drive technical and non-technical security strategies. Skilled in mentoring, motivating, and managing multinational teams, with a commitment to continual improvement and innovation in the cybersecurity landscape. Accelerating vulnerability discovery and remediation before threat actors find them.

Experience

  1. Director of Application and Product Security

    Aon

    Sep 2022 — Present · Remote, UT, US

    Owning of organization-wide security assessments for Web Application Assessments, Mobile Assessments, Internal and External Network Assessments, Threat Actor Simulations, Cloud Assessments (AWS and Azure), Red/Purple Team Assessments, and Threat Modeling; resulting in a 40% decrease in external security incidents- Collaborated with leaders across infrastructure, product engineering, operations, and legal to integrate trust and security principles throughout the product lifecycle (SDLC)- Leveraged risk assessments to provide strategic direction to integrate security into software lifecycles, infrastructure roadmaps, and developer security training opportunities- Designed and implemented security strategies that align with business objectives, KPIs, industry best practices, and threat intelligence trends- Utilized threat intelligence trends and aligned assessment methodologies with MITRE ATT & CK and NIST 800-115 to emulate adversarial assessments against organization-wide security controls- Developed and delivered security maturity and risk exposure reports to executive leadership using tailored dashboards and KPIs- Redesigned assessment policy, processes, and methodologies, increasing productivity by 81% and identifying 34% more high-risk vulnerabilities per assessment- Developed metrics and analytics that identify key performance drivers, strategies, and opportunities for team enhancements- Lead the security initiative to mature vulnerability management policies and procedures- Lead the security assessment of multiple AI features (LLMs)- Delivered offensive security recommendations for 20+ organization wide incidents assisting with triage and leading remediation validation- Launched the vulnerability disclosure program (bug bounty), and DAST/SAST/SCA SDLC integration program- Manage, mentor, and motivate 10 multi-national team members- Created service offerings a methodologies for 6 new assessment types

Education

  • Western Governors University

    Master of Business Administration - MBA, Information Technology

  • Brigham Young University

    Bachelor of Science (BS), Computer Science

Find verified contacts for anyone on LinkedIn

Unifers gives sales teams verified emails and direct dials, enriched profiles, and outreach that lands in the inbox.

Free plan included · No credit card required

This profile is compiled from publicly available professional sources. Unifers is not affiliated with or endorsed by LinkedIn. Request removal of this profile.

Kevin Ostrin — Director of Application and Product Security at Aon in Lehi, UT, US | Unifers